JFrog Artifactory flaw can hand out admin access

Published August 28, 2026 CVE-2026-82329

JFrog Artifactory, a tool companies use to store and manage their software packages, has a login weakness. In its default setup, someone with network access can reach it without a password and gain full administrator control.

Severity
CriticalCVSS 3.1 · 9.8
Fix
Update availableFix recorded on Sep 2, 2026
Affected versions
before 7.111.21; 7.117.0 to before 7.117.28; 7.125.0 to before 7.125.20+3 more
Weakness
CWE-287Improper Authentication
Exploit likelihood
7.7% in 30 daysEPSS, higher than 94% of known flaws
Affects
Artifactory
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Sep 2, 2026
Federal fix deadline
Sep 5, 2026

What to do

There is no published affected or fixed version number yet, so check the JFrog Artifactory admin console and the official JFrog security advisories page for a version-specific fix.

Until JFrog publishes a version-specific patch, restrict network access to the Artifactory admin interface so it is not reachable from untrusted networks, and review its authentication configuration for anything left at default.

Technical details

CVE-2026-82329 (CVSS 9.8, critical) describes an improper authentication weakness (CWE-287) in JFrog Artifactory. Under default configuration, an unauthenticated attacker with network access to the instance may be able to obtain administrative privileges. NVD has not yet published affected or fixed version ranges, and no vendor advisory, proof-of-concept, or technical write-up was found beyond the NVD record itself.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator